Automatic Power Trace Alignment for Side-Channel Analysis | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Automatic Power Trace Alignment for Side-Channel Analysis Sying-Jyan Wang, Yi-Chi Lin, Katherine Shu-Min Li, Chen-Yeh Lin, and 1 more This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-2995521/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract Data encryption is critical for information security. Previous studies show that power analysis is a powerful tool for side-channel attack (SCA) against cryptographic modules. Therefore, it is essential to carry out power analysis to assess the vulnerability of cryptographic modules. The success of power analysis relies on aligned power traces, which is not easy without an external trigger point. Locating cryptographic operations in a power trace can be tedious, so it is desirable if we can achieve automatic power trace alignment. In this paper, we propose an automatic power trace alignment method so that operations in power traces and be located without external trigger points. Experimental results show that the proposed method can be applied to various ciphers, including AES, RSA, and ECC. side-channel attack (SCA) power analysis power trace AES RSA ECC Figures Figure 1 Figure 2 Figure 3 Figure 4 Figure 5 Figure 6 Figure 7 Figure 8 Figure 9 1. INTRODUCTION Information and communication technology (ICT) is the foundation of modern society, and the applications of ICT have grown rapidly. When the security of ICT products is compromised, the end users may experience serious loss of life or property. Therefore, ensuring information security is an important consideration in the deployment of ICT products. With the progress of globalization, the supply chain of ICT products is gradually scattered all over the world, and ensuring the safety of these products has become a challenging problem [1-4]. Ensuring information security is usually done with the help of various security functions. Data encryption is the basis of security functions, and modern data encryption technology requires a chip to execute a complex cryptographic algorithm. Therefore, the security level of the chip executing cryptographic algorithms has a profound impact on the security of ICT products. Most cryptographic systems in use have been proved to secure enough to resist attacks based on cryptanalysis. On the other hand, side-channel analysis (SCA) of the cryptographic modules can reveal critical security parameters (CSP), including secret keys used for encryption [5-6]. Many SCA methods have been developed, including include timing analysis (TA) [7] and power analysis, and previous studies show that power analysis based attacks are more powerful. Many power analysis methods have been developed, including simple power analysis (SPA) [8], differential power analysis (DPA) [9], correlational power analysis (CPA), [10], profiling attacks [11-14], and test vector leakage assessment (TVLA) [15], etc. Therefore, the ability to resist side-channel analysis should also be a factor for the procurement of ICT products. The security level of the product must be evaluated by an impartial professional testing laboratory, and the ability to perform SCA is a necessary condition for the establishment of a testing laboratory. Performing power analysis requires not only advanced knowledge about the target cryptographic algorithm but also special equipment (e.g. oscilloscope). In addition, the power traces must be perfectly aligned such that meaningful analyses can be carried out. In ISO/IEC 17825 [16], it is suggested that in testing mode the device may provide an external trigger point to indicate the start or stop of the cryptographic operation. However, this approach actually renders the device more vulnerable to SCA attacks, so it may be difficult to convince device vendors to provide such a trigger point. In this case, the alignment still has to be carried out manually. Automatic locating encryption operations in power traces will facilitate power analysis, but the problem is rarely studied in the literature. In the work of Tian et al. [17-18], it is assumed that the part of the encryption round in a power trace will generate the peak power consumption. Under this assumption, they will “manually” select the part of the encryption round, and then use the correlation coefficient to locate the encryption round positions. Trautmann et al. [19] assume that a power trace contains multiple cryptographic operations (CO), and they will identify the most likely pattern of one encryption operation, and then use this pattern to determine the exact locations of other encryption operations in the power trace by means of correlation analysis. The results show that their method is effective for various implementations of AES, but asymmetric encryption algorithms are not studied in this work. Furthermore, the required computation resources are non-trivial, as a complete CO is used to calculate correlation coefficients. In general, GPU are used to accelerate the process [19]. In this paper, we propose an automatic power trace alignment method that enables analyzers to locate operations in power traces without the help of a trigger signal. Experimental results show that the proposed method can be applied to various encryption methods with repeated operations, including Advanced Encryption Standard (AES), RSA, and Elliptic Curve Cryptography (ECC). 2. PROPOSED METHOD 2.1. Motivation Modern cryptographic algorithms rely on repeatedly executing numerical operations on the plaintext using a encryption key. The partial power traces corresponding to the same numerical operations are similar even if the operands are different. For example, the AES-128 consists of nine rounds of identical operations (SubByte, ShiftRow, MixColumn, AddRoundKey) while the last round is slightly different. For RSA, the computation required for a key bit ‘0’ is the square operation while the operations for key bit ‘1’ is square and multiplication. For example, Fig. 1 gives the partial power trace of an AES encryption process. It can be seen that there are five similar segments in the partial power trace corresponding to five encryption rounds of AES. Since the purpose of power analysis is to retrieve the key bits involved in a cryptographic operation, what we really need to achieve is to locate the exact locations of all related computations in the power trace of a CO instead of the entire CO. There are two major advantages of this approach. First, the power analysis will be easier if we can determine the exact locations of the computations executed in a CO. Secondly, locating a single round in a CO is much more efficient than locating the entire CO in terms of the required computation resource. 2.2. Proposed Method Pre-processing In synchronous sequential circuits, a significant part of the power consumption is attributed to the clock distribution network. Since the power consumption due to the clocking network always exists, it can be regarded as noise in nature. To achieve a cleaner power trace, we can remove the clocking power before the actual power trace alignment process. Given a power trace pt , we can get the power spectrum PT by executing fast Fourier transform (FFT) on pt . Let the clock frequency be f 0 , we can remove the effect of clocking power by removing the components at f 0 and its harmonics (i.e., multiples of f 0 ) in PT . The modified PT is then converted back to the time domain through inverse FFT (IFFT) to retrieve a cleaner power trace. Fig. 2 gives the result of pre-processing for the power trance given in Fig. 1, and it can be seen that the encryption round are easier to identify in the processed power trace. Automatic Locating Cryptographic Computation If a cryptographic operation consists of repeated computations, we will find similar patterns appear repeatedly in the corresponding power trace. Therefore, we can achieve automatic power trace alignment by determining the locations of the target computation. In this section, the basic is explained through AES-128. However, the method can be applied to other cryptographic algorithms as well, as we will see in the next section. AES-128 is carried out by executing 9 identical rounds, so it can be expected that if we extract a pattern belongs to the power trace of one round, overall we will be able to find 9 matching parts in the entire power trace (including itself). There is no need to set the pattern length equal to the exact time to execute a single round, but more accurate results can be achieved when the pattern length is close to an encryption round. Given a power trace of length N . First we need to select a window size w to select patterns in the power trace. The window width should be close to the length of an encryption round. When the window is position at time t , the selected pattern is located between time t and t+w . For example, Fig. 3 gives the entire power trace of an AES-128 encryption process, and the red box is the window at time 0. Since we do not know where the starting position of the first round is, we will start looking at time 0. The reference window will move to the next position in each iteration. In other words, the reference sliding window in iteration i is the window starts at time i . In iteration i , we will calculate the similarity between the pattern in the reference window and every window j , 0 £ j £ N – w . The similarity between the two patterns is estimated by calculating the correlation coefficient r i , j for the two windows. Let X and Y be both two series of length w the correlation coefficient between X and Y is defined as follows. In Eq. (1), X k is the k -th element in pattern X and X̅ is the mean of X , while Y k and Ȳ are similarly defined for pattern Y . The results of the above computation in iteration i form a time series of the correlation coefficients representing the similarity between the reference window and every other widow in the power trace. The time series of correlation coefficients obtained from the above procedure will cover all patterns of length w in the given power trace. Taking AES-128 as an example, if reference window i is at the the starting position of an encryption round, we should have 9 peaks close or equal to 1 in the time series of correlation coefficients, in which r i , i = 1 while the other eight peaks gives the starting positions of the other encryption/decryption rounds. In order to facilitate the searching procedure, we can select a threshold value T such that position j is judged as the starting position of a round if correlation coefficient r i , j is larger than T . The overall procedure is outlined in Algorithm 1. In iteration i of the algorithm, the correlation coefficients are only calculated between reference window i and other windows j , j ³ i (line 4) so that exact 9 qualified peaks will be found if a round starts at position i . There is no need to calculate correlation coefficients r i , j , j < i , as they have been calculated in previous iterations already. Algorithm 1: Locating the encryption rounds Input: trace : a power trace; w : Window size; T : Threshold; r_count : number of encryption round/operation; Output: Locations of encryption rounds 1 for i = 0 to trace . length – w do 2 peak_N ← 0 3 ref ← trace [ i:i+w ] 4 for j = i to trace . length - w do 5 corr ← correlation_coefficient( ref , trace [ j:j+ w ]) 6 if corr > T then 7 peak_N = peak_N + 1 8 end 9 if peak_N == r_count then 10 return ref 11 end 3. EXPERIMENTAL RESULTS FOR AES AND DISCUSSION The proposed method is validated using NewAE ChipWhisper-Lite development board [20], while the encryption algorithm is AES-128. The encryption clock rate is 7.34 MHz while the sampling rate is four times of the encryption clock rate. The proposed method can be applied as long as the window size is not too far away from the exact length of an encryption round, and the effect of varying window width will be analyzed later. 3.1. AES Result We use the power trace given in Fig. 3 as the example. In this experiment, we set window size w =4552 and threshold T =0.9. Fig. 4(a) gives the time series of correlation coefficients for reference window 0 (i.e., the red box in Fig. 3). It can be seen that r 0,0 =1 while all other correlation coefficients are smaller than 0.6. The result indicates that position 0 does not start an encryption round. Fig. 4(b) illustrates the time series of correlation coefficients for reference window 3790, which is the starting position of the first encryption round. It can be seen that there are 9 peaks whose values are very close to 1, and the value is equal to 1 at position 3790. The results indicate that we have successfully locate the first 9 encryption rounds. 3.2. Effect of Pre-processing Results in Fig. 4(b) are obtained from the pre-processed power trace. In order to demonstrate the effect of pre-processing, we also calculate the correlation coefficients obtained from the original power trace (i.e., without pre-processing), and the results are provided in Fig. 5. In this case, the difference between peak and non-peak values are significantly smaller. 3.3. Effect of Window Size The impact of varying window size is assessed through experiment, and the general is outlined as follows. (1) First, a pre-processed power trace is selected, with the reference window located at the starting position of the first round. (2) Let the length of an encryption round be W . In each try, the window size is set to α W , where α is a real number used to adjust the window size. (3) Execute Algorithm 1 to find out set P of all qualified peak values. (4) Let # IR be the number of identical rounds in the encryption process. The normalized peak value NP is defined as . When all the identical rounds are correctly identified, NP should be smaller than 1 but also very close to 1. The experiment is carried out using the power trace given in Fig. 3. Since the encryption algorithm is AES-128, # IR is 9. We have executed the above procedure with various window sizes, and the results are summarized in Table 1 The results show that the proposed method is effective in the range between 0.5´ W to W . Table 1. Window size vs. normalized peak value. α 0.005 0.01 0.5 1.0 1.5 2.0 2.5 3.0 NP 19.662 1.431 0.981 0.985 0.876 0.877 0.768 0.768 The reasons that smaller and larger window sizes cannot be used are explained through examples in Fig. 6, in which two time series of correlation coefficients are plotted for α=0.005 and α=2. In the case of a small window size (α=0.005), many similar patterns can be found in the power trace, leading to many correlation coefficients larger than threshold T , as shown in shown in Fig. 6(a). As a result, the cardinality of set P , returned by Algorithm 1, will increase if the window size shrinks. On the other hand, if the window size is 2 W , only the first 8 rounds can be correctly located, as shown in Fig. 6(b). In this case, the reference window contains the pattern consisting of the first two rounds, while each peak in Fig. 6(b) matches a pattern covering two consecutive encryption rounds. The sliding window at the starting position of round 9 convers the last two rounds; however, since the operations in the last round is not the same as the other 9 rounds, the correlation coefficient is relatively small. Obviously, the best choice of window size should be W . However, if initially W is unknown, one can apply the following procedure to determine W . (1) From a given power trace, manually select a window size that falls between W and W /2. (2) Execute Algorithm 1 to find out peaks. (3) W is the distance between two consecutive peaks. 4. APPLICATION TO OTHER CRYPTOGRAPHIC ALGORITHMS The proposed method can also be used to locate computation operations in the power traces of other cryptographic algorithms. The cases of RSA and ECC are studied in this section. 4.1. RSA 4.1.1. Regular Implementation The encryption process of RSA involves repeated modular exponentiation operations. In the process, the square operation will be executed in every key bit while an additional multiplication operation is executed if the key bit is 1. Therefore, we need to find the patterns corresponding to the square operations to locate encryption operations, so the window size should be close to the time period used for the square operation. Fig. 7(a) gives a power trace of RSA encryption in which the key length is 16, while Fig. 7(b) show the results of round locating. In this experiment, the window size is w =5100 sampling periods, which is the time required to complete a square operation. It can be seen that exact 16 qualified peaks appear in Fig. 16(b). In this case, the proposed method can also be used for SPA, as the distance between two consecutive peaks can be used to extract the corresponding key bit. There are two types of distances; the longer distance implies that the corresponding bey bit is ‘1’ while the shorter distance means the key bit is ‘0’. The 16 peaks in Fig. 7(b) can be used to extract the first 15 bits of the encryption key, which is 1000_0001_0100_000x. The last key bit cannot be identified directly using the proposed method. 4.1.2. Implementation with Montgomery Power Ladder The execution time variation due to different key bit values can be eliminated by using Montgomery power ladder (MPL) [21]. In this case, the proposed method cannot be used for SPA; still, the locations of every bit can be located in the process. An example is shown in Fig. 8, in which Fig. 8(a) gives the power trace and Fig. 8(b) is the locating results obtained with w =2220. It can be seen that 16 peaks appear in Fig. 8(b), while all distances between consecutive peaks are roughly equal. 4.2. ECC In the encryption process of ECC, the “double” operation is executed for all key bits while “add” is executed only if the key bit is ‘1’. Therefore, in a straightforward implementation of ECC, the locating process is similar to that of RSA. In this case, we need to locate “double” operations in a power trace. An example is given in Fig. 9. Fig. 9(a) is the power trace of an ECC encryption with a 8-bit key, while Fig. 8(b) is obtained by locating “double” operations with w =5100.. It is clear that there are 8 peaks in Fig. 9(b), which indicates that computation operations corresponding to the 8 key bits are located. Furthermore, the peak positions can be used for SPA, since a longer distance between two peaks imply the computation is for key bit ‘1’. From Fig. 9(b), it can be seen that the encryption key is 1010_010x. MPL has also been proposed as a countermeasure to SPA for ECC [21]. In this case, the locating results are peaks separated by the same distance. The process is similar to that of RSA with MPL. 5. CONCLUSION We propose a method for automatic location of cryptographic operations in power traces. The proposed method is achieved by using sliding windows to calculate correlation coefficients that are used to locate encryption rounds in AES. Experimental results show that the proposed method can effectively locate encryption rounds in AES, and the method is applicable to other cryptographic algorithms as well, including RSA and ECC. This approach gives test laboratories the means to perform side-channel analysis without the need for additional trigger signals. Compared with previous methods, the proposed method can achieve accurate power trace alignment with lower computation resources. References Tehranipoor M., Wang C. (eds.): Introduction to Hardware Security and Trust. Springer (2012) Goertzel K.M., Hamilton B.A. Integrated circuit security threats and hardware assurance countermeasures. CrossTalk 26(6), 33-38 (2013) Rostami M., Koushanfar F., Karri R.: A primer on hardware security: models, methods, and metrics. Proc. IEEE 102(8), 1283–1295 (2014) Sklavos N., Chaves R., Di Natale G., Regazzoni F. (eds.): Hardware Security and Trust, Springer (2017) Das D., Maity S., Nasir S.B., Ghosh S., Raychowdhury A., Sen S. High efficiency power side-channel attack immunity using noise injection in attenuated signature domain. In Proc. 2017 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 62-67 (2017) Das D. et al.: ASNI: attenuated signature noise injection for low-overhead power side-channel attack immunity. IEEE Trans. CAS-I 65(10), 3300–3311 (2018) Kocher, P.C.: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In: Koblitz, N. (eds) Advances in Cryptology — CRYPTO ’96. LNCS 1109. Springer, Berlin, Heidelberg (1996). Mayer-Sommer, R.: Smartly analyzing the simplicity and the power of simple power analysis on smartcards. In: Koç, Ç.K., Paar, C. (eds) Cryptographic Hardware and Embedded Systems — CHES 2000. NCS 1965. Springer, Berlin, Heidelberg (2000) Kocher, P., Jaffe, J., Jun, B.: Differential Power Analysis. In: Wiener, M. (eds) Advances in Cryptology - CRYPTO’ 99, LNCS 1666, 388–397. Springer, Berlin, Heidelberg. Springer (1999) Brier, E., Clavier, C., Olivier, F.: Correlation power Analysis with a leakage model. In: Joye, M., Quisquater, JJ. (eds) Cryptographic Hardware and Embedded Systems (CHES 2004), LNCS 3156. Springer, Berlin, Heidelberg (2004) Rechberger, C., Oswald, E.: Practical template attacks. In: Lim, C.H., Yung, M. (eds) Information Security Applications (WISA 2004), LNCS 3325, 440-456,. Springer, Berlin, Heidelberg (2005). Hospodar, G., Gierlichs, B., De Mulder, E. et al.: Machine learning in side-channel analysis: a first study. J. Cryptogr. Eng. 1, 293–302 (2011) Lerman, L., Poussier, R., Markowitch, O. et al.: Template attacks versus machine learning revisited and the curse of dimensionality in side-channel analysis: extended version. J. Cryptogr. Eng. 8, 301–313 (2018) Bartkewitz, T., Lemke-Rust, K.: Efficient template attacks based on probabilistic multi-class support vector machines. In: Mangard, S. (eds) Smart Card Research and Advanced Applications (CARDIS 2012), LNCS 7771, 263–276. Springer, Berlin, Heidelberg (2013) Becker G., et al.: Test vector leakage assessment (tvla) methodology in practice. Proc. Intl. Cryptographic Module Conf. (2013) ISO/IEC 17825. https://www.iso.org/standard/60612.html. Tian Q., Shoufan A., Stoettinger M., Huss S.H.: Power trace alignment for cryptosystems featuring random frequency countermeasures. Proc. 2012 IEEE Second International Conference on Digital Information Processing and Communications (ICDIPC), 51-55. IEEE (2012) Tian Q., Huss S.H.: A general approach to power trace alignment for the assessment of side-channel resistance of hardened cryptosystems. Proc. 2012 IEEE Eighth International Conference on Intelligent Information Hiding and Multimedia Signal Processing, 465-470. IEEE (2012) Trautmann, et al.: Semi-automatic locating of cryptographic operations in side-channel traces. IACR Trans. Cryptographic Hardware and Embedded Systems (TCHES), 2022(1), 345-366. (2022) https://www.newae.com/chipwhisperer. Joye, M., Yen, SM.: The Montgomery Powering Ladder. In: Kaliski, B.S., Koç, ç.K., Paar, C. (eds) Cryptographic Hardware and Embedded Systems (CHES 2002), LNCS 2523. Springer, Berlin, Heidelberg (2003). Additional Declarations No competing interests reported. Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-2995521","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":205543415,"identity":"f5d4cc82-27ce-448f-b066-2a05af9f8dec","order_by":0,"name":"Sying-Jyan Wang","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAAA50lEQVRIiWNgGAWjYFCCAyDCBsxkRggQ1pKGooWxgQirDpOgRb7xjOHngl/n5eUbeA9+LmxjkOO7kcD+mAePFoMDZ4ylZ/bdNtxwgC9ZemYbg7HkjQTGZrxaGM5ukObtuZ1gwMBjxszbxpC4AaQlB5/DGs5u/s3bcy5BvgGipZ6gFoYDZ7dJ8/w4kMBwAKIlwYCQFoMD579Z8zYkG244zGMszXNOwnDmmYeNs//gc9iMY8m3ef7Yycu39xh+5imzkec7nnzg4wx8DpM4wMDA2MYAixQJICYUk/wgeXzuGAWjYBSMglEAAJW+Tk2UHOxGAAAAAElFTkSuQmCC","orcid":"","institution":"National Chung Hsing University","correspondingAuthor":true,"prefix":"","firstName":"Sying-Jyan","middleName":"","lastName":"Wang","suffix":""},{"id":205543417,"identity":"88783cfa-a44e-4cc3-97a4-e35ff4204929","order_by":1,"name":"Yi-Chi Lin","email":"","orcid":"","institution":"National Chung Hsing University","correspondingAuthor":false,"prefix":"","firstName":"Yi-Chi","middleName":"","lastName":"Lin","suffix":""},{"id":205543419,"identity":"13cf94b2-4e04-408f-a994-20f253bfac9d","order_by":2,"name":"Katherine Shu-Min Li","email":"","orcid":"","institution":"National Sun Yat-sen University University","correspondingAuthor":false,"prefix":"","firstName":"Katherine","middleName":"Shu-Min","lastName":"Li","suffix":""},{"id":205543421,"identity":"4f05d82c-d10a-4553-93ef-c264b743e1bb","order_by":3,"name":"Chen-Yeh Lin","email":"","orcid":"","institution":"Cybersecurity Technology Institute Institute for Information Industry Taipei","correspondingAuthor":false,"prefix":"","firstName":"Chen-Yeh","middleName":"","lastName":"Lin","suffix":""},{"id":205543423,"identity":"cd2d8df9-915a-4e72-97b9-f3e8d2fdce8a","order_by":4,"name":"Song-Kong Chong","email":"","orcid":"","institution":"Cybersecurity Technology Institute Institute for Information Industry Taipei","correspondingAuthor":false,"prefix":"","firstName":"Song-Kong","middleName":"","lastName":"Chong","suffix":""}],"badges":[],"createdAt":"2023-05-29 12:14:29","currentVersionCode":1,"declarations":"","doi":"10.21203/rs.3.rs-2995521/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-2995521/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":37917469,"identity":"12726fa0-195a-4b12-b823-cb392cd489d2","added_by":"auto","created_at":"2023-06-02 14:58:24","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":87812,"visible":true,"origin":"","legend":"\u003cp\u003eA partial power trace of an AES encryption process.\u003c/p\u003e","description":"","filename":"1.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/d99d96ad54d584b941c39ba8.png"},{"id":37917475,"identity":"7a27877b-da0e-401c-b7cc-f6006dcee163","added_by":"auto","created_at":"2023-06-02 14:58:24","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":135199,"visible":true,"origin":"","legend":"\u003cp\u003eThe pre-process power trace corresponding to the one in Fig. 1.\u003c/p\u003e","description":"","filename":"2.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/642469077fe9c60371fbe073.png"},{"id":37918460,"identity":"8ebf2d3e-70db-487f-893d-a6421534f86a","added_by":"auto","created_at":"2023-06-02 15:06:24","extension":"png","order_by":3,"title":"Figure 3","display":"","copyAsset":false,"role":"figure","size":66803,"visible":true,"origin":"","legend":"\u003cp\u003eLocating encryption rounds using sliding window.\u003c/p\u003e","description":"","filename":"3.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/58c87c9cd875466a4c3cd737.png"},{"id":37918458,"identity":"0c47f55e-b189-415b-bc6a-8402b88c97fe","added_by":"auto","created_at":"2023-06-02 15:06:24","extension":"png","order_by":4,"title":"Figure 4","display":"","copyAsset":false,"role":"figure","size":48250,"visible":true,"origin":"","legend":"\u003cp\u003eTime series of correlation coefficients: (a) reference window 0, (b) reference window 3790.\u003c/p\u003e","description":"","filename":"4.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/a67e585d7eb86bf12dca747c.png"},{"id":37918461,"identity":"b8aebf7b-42b6-436c-b204-e851642697d2","added_by":"auto","created_at":"2023-06-02 15:06:24","extension":"png","order_by":5,"title":"Figure 5","display":"","copyAsset":false,"role":"figure","size":26009,"visible":true,"origin":"","legend":"\u003cp\u003eTime series of correlation coefficients for reference window 3790 without pre-processing.\u003c/p\u003e","description":"","filename":"5.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/81c4189a5104cb584077f724.png"},{"id":37917473,"identity":"6e0d6d98-638d-452c-8cb3-4015e9167141","added_by":"auto","created_at":"2023-06-02 14:58:24","extension":"png","order_by":6,"title":"Figure 6","display":"","copyAsset":false,"role":"figure","size":72722,"visible":true,"origin":"","legend":"\u003cp\u003eTime series of correlation coefficients for various window sizes: (α) α=0.005, (b) α=2.\u003c/p\u003e","description":"","filename":"6.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/c2939917681e1277a6dab307.png"},{"id":37919481,"identity":"8fd050af-2b4d-4dd7-9d15-428f68658309","added_by":"auto","created_at":"2023-06-02 15:14:24","extension":"png","order_by":7,"title":"Figure 7","display":"","copyAsset":false,"role":"figure","size":86542,"visible":true,"origin":"","legend":"\u003cp\u003e(a) A power trace of the straightforward implementation of RSA, (b) results of locating “square” operations.\u003c/p\u003e","description":"","filename":"7.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/eb4ec4258e7d7b6c5fc0ce33.png"},{"id":37917470,"identity":"8e7cc09b-11d8-4583-862a-05e16ee9d64c","added_by":"auto","created_at":"2023-06-02 14:58:24","extension":"png","order_by":8,"title":"Figure 8","display":"","copyAsset":false,"role":"figure","size":86472,"visible":true,"origin":"","legend":"\u003cp\u003e(a) Power trace of RSA implemented with MPL, (b) results of locating “square” operations.\u003c/p\u003e","description":"","filename":"8.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/3d49698fa256ac13be836552.png"},{"id":37918462,"identity":"99f1d952-4c85-4b10-9519-70e9d0db1280","added_by":"auto","created_at":"2023-06-02 15:06:24","extension":"png","order_by":9,"title":"Figure 9","display":"","copyAsset":false,"role":"figure","size":95812,"visible":true,"origin":"","legend":"\u003cp\u003e(a) A power trace of the straightforward implementation of ECC, (b) results of locating “double” operations.\u003c/p\u003e","description":"","filename":"9.png","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/ad9be659db040555538595ca.png"},{"id":38642030,"identity":"365f16d3-3ba5-4a8b-ba83-a57ca35e7a45","added_by":"auto","created_at":"2023-06-16 06:44:36","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":1176454,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-2995521/v1/4720dea9-ca3a-4596-a35e-13a65ed76043.pdf"}],"financialInterests":"No competing interests reported.","formattedTitle":"Automatic Power Trace Alignment for Side-Channel Analysis","fulltext":[{"header":"1. INTRODUCTION","content":"\u003cp\u003eInformation and communication technology (ICT) is the foundation of modern society, and the applications of ICT have grown rapidly. When the security of ICT products is compromised, the end users may experience serious loss of life or property. Therefore, ensuring information security is an important consideration in the deployment of ICT products. With the progress of globalization, the supply chain of ICT products is gradually scattered all over the world, and ensuring the safety of these products has become a challenging problem [1-4].\u003c/p\u003e\n\u003cp\u003eEnsuring information security is usually done with the help of various security functions. Data encryption is the basis of security functions, and modern data encryption technology requires a chip to execute a complex cryptographic algorithm. Therefore, the security level of the chip executing cryptographic algorithms has a profound impact on the security of ICT products.\u003c/p\u003e\n\u003cp\u003eMost cryptographic systems in use have been proved to secure enough to resist attacks based on cryptanalysis. On the other hand, side-channel analysis (SCA) of the cryptographic modules can reveal critical security parameters (CSP), including secret keys used for encryption [5-6]. Many SCA methods have been developed, including include timing analysis (TA) [7] and power analysis, and previous studies show that power analysis based attacks are more powerful. Many power analysis methods have been developed, including simple power analysis (SPA) [8], differential power analysis (DPA) [9], correlational power analysis (CPA), [10], profiling attacks [11-14], and test vector leakage assessment (TVLA) [15], etc. Therefore, the ability to resist side-channel analysis should also be a factor for the procurement of ICT products.\u003c/p\u003e\n\u003cp\u003eThe security level of the product must be evaluated by an impartial professional testing laboratory, and the ability to perform SCA is a necessary condition for the establishment of a testing laboratory. Performing power analysis requires not only advanced knowledge about the target cryptographic algorithm but also special equipment (e.g. oscilloscope). In addition, the power traces must be perfectly aligned such that meaningful analyses can be carried out. In ISO/IEC 17825 [16], it is suggested that in testing mode the device may provide an external trigger point to indicate the start or stop of the cryptographic operation. However, this approach actually renders the device more vulnerable to SCA attacks, so it may be difficult to convince device vendors to provide such a trigger point. In this case, the alignment still has to be carried out manually.\u003c/p\u003e\n\u003cp\u003eAutomatic locating encryption operations in power traces will facilitate power analysis, but the problem is rarely studied in the literature. In the work of Tian \u003cem\u003eet al.\u003c/em\u003e [17-18], it is assumed that the part of the encryption round in a power trace will generate the peak power consumption. Under this assumption, they will \u0026ldquo;manually\u0026rdquo; select the part of the encryption round, and then use the correlation coefficient to locate the encryption round positions. Trautmann \u003cem\u003eet al.\u003c/em\u003e [19] assume that a power trace contains multiple cryptographic operations (CO), and they will identify the most likely pattern of one encryption operation, and then use this pattern to determine the exact locations of other encryption operations in the power trace by means of correlation analysis. The results show that their method is effective for various implementations of AES, but asymmetric encryption algorithms are not studied in this work. Furthermore, the required computation resources are non-trivial, as a complete CO is used to calculate correlation coefficients. In general, GPU are used to accelerate the process [19].\u003c/p\u003e\n\u003cp\u003eIn this paper, we propose an automatic power trace alignment method that enables analyzers to locate operations in power traces without the help of a trigger signal. Experimental results show that the proposed method can be applied to various encryption methods with repeated operations, including Advanced Encryption Standard (AES), RSA, and Elliptic Curve Cryptography (ECC). \u0026nbsp;\u003c/p\u003e"},{"header":"2.\tPROPOSED METHOD","content":"\u003ch2\u003e2.1. Motivation\u003c/h2\u003e\n\u003cp\u003eModern cryptographic algorithms rely on repeatedly executing numerical operations on the plaintext using a encryption key. The partial power traces corresponding to the same numerical operations are similar even if the operands are different. For example, the AES-128 consists of nine rounds of identical operations (SubByte, ShiftRow, MixColumn, AddRoundKey) while the last round is slightly different. For RSA, the computation required for a key bit \u0026lsquo;0\u0026rsquo; is the square operation while the operations for key bit \u0026lsquo;1\u0026rsquo; is square and multiplication. For example, Fig. 1 gives the partial power trace of an AES encryption process. It can be seen that there are five similar segments in the partial power trace corresponding to five encryption rounds of AES.\u003c/p\u003e\n\u003cp\u003eSince the purpose of power analysis is to retrieve the key bits involved in a cryptographic operation, what we really need to achieve is to locate the exact locations of all related computations in the power trace of a CO instead of the entire CO. There are two major advantages of this approach. First, the power analysis will be easier if we can determine the exact locations of the computations executed in a CO. Secondly, locating a single round in a CO is much more efficient than locating the entire CO in terms of the required computation resource.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e\n\u003ch2\u003e2.2. Proposed Method\u003c/h2\u003e\n\u003ch3\u003ePre-processing\u003c/h3\u003e\n\u003cp\u003eIn synchronous sequential circuits, a significant part of the power consumption is attributed to the clock distribution network. Since the power consumption due to the clocking network always exists, it can be regarded as noise in nature.\u0026nbsp;To achieve a cleaner power trace, we can remove the clocking power before the actual power trace alignment process. Given a power trace\u003cem\u003e\u0026nbsp;pt\u003c/em\u003e, we can get the power spectrum \u003cem\u003ePT\u003c/em\u003e by executing fast Fourier transform (FFT) on \u003cem\u003ept\u003c/em\u003e. Let the clock frequency be \u003cem\u003ef\u003c/em\u003e\u003csub\u003e0\u003c/sub\u003e, we can remove the effect of clocking power by removing the components at \u003cem\u003ef\u003c/em\u003e\u003csub\u003e0\u003c/sub\u003e and its harmonics (i.e., multiples of \u003cem\u003ef\u003c/em\u003e\u003csub\u003e0\u003c/sub\u003e) in \u003cem\u003ePT\u003c/em\u003e. The modified \u003cem\u003ePT\u003c/em\u003e is then converted back to the time domain through inverse FFT (IFFT) to retrieve a cleaner power trace. Fig. 2 gives the result of pre-processing for the power trance given in Fig. 1, and it can be seen that the encryption round are easier to identify in the processed power trace.\u003c/p\u003e\n\u003cp\u003eAutomatic Locating Cryptographic Computation\u003c/p\u003e\n\u003cp\u003eIf a cryptographic operation consists of repeated computations, we will find similar patterns appear repeatedly in the corresponding power trace. Therefore, we can achieve automatic power trace alignment by determining the locations of the target computation. In this section, the basic is explained through AES-128. However, the method can be applied to other cryptographic algorithms as well, as we will see in the next section.\u003c/p\u003e\n\u003cp\u003eAES-128 is carried out by executing 9 identical rounds, so it can be expected that if we extract a pattern belongs to the power trace of one round, overall we will be able to find 9 matching parts in the entire power trace (including itself). There is no need to set the pattern length equal to the exact time to execute a single round, but more accurate results can be achieved when the pattern length is close to an encryption round.\u003c/p\u003e\n\u003cp\u003eGiven a power trace of length \u003cem\u003eN\u003c/em\u003e. First we need to select a window size \u003cem\u003ew\u003c/em\u003e to select patterns in the power trace. The window width should be close to the length of an encryption round. When the window is position at time \u003cem\u003et\u003c/em\u003e, the selected pattern is located between time \u003cem\u003et\u003c/em\u003e and \u003cem\u003et+w\u003c/em\u003e. For example, Fig. 3 gives the entire power trace of an AES-128 encryption process, and the red box is the window at time 0.\u003c/p\u003e\n\u003cp\u003eSince we do not know where the starting position of the first round is, we will start looking at time 0. The reference window will move to the next position in each iteration. In other words, the reference sliding window in iteration \u003cem\u003ei\u003c/em\u003e is the window starts at time \u003cem\u003ei\u003c/em\u003e. In iteration \u003cem\u003ei\u003c/em\u003e, we will calculate the similarity between the pattern in the reference window and every window \u003cem\u003ej\u003c/em\u003e, 0 \u0026pound; \u003cem\u003ej\u003c/em\u003e \u0026pound; \u003cem\u003eN\u003c/em\u003e\u0026ndash;\u003cem\u003ew\u003c/em\u003e. The similarity between the two patterns is estimated by calculating the correlation coefficient \u003cem\u003er\u003csub\u003ei\u003c/sub\u003e\u003c/em\u003e\u003csub\u003e,\u003cem\u003ej\u003c/em\u003e\u003c/sub\u003e for the two windows. Let \u003cem\u003eX\u003c/em\u003e and \u003cem\u003eY\u003c/em\u003e be both two series of length \u003cem\u003ew\u003c/em\u003e the correlation coefficient between \u003cem\u003eX\u003c/em\u003e and \u003cem\u003eY\u003c/em\u003e is defined as follows.\u003c/p\u003e\n\u003cp\u003e\u003cimg src=\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAVsAAAAuCAYAAACGV7orAAALNklEQVR4nO2dv2vb0BbHjx9vbajI2NLBylI6eBEe2mJIIJEpGdPKY6BDsTsFStI4zZSGVG5DlzZxhkIopHKhYxwSChlqJ5A2BHvrUHkwdJMT2v4B5w3h6km2JEuOZMv2+YAg1g/fe0+so6t7v+eeCCIiEARBEIHyn15XgCAIYhggZ0sQBNEFyNkSoSMSibRsuVyu19VyRT/XnQiWCI3ZEgRBBA/1bENELpez7BmxrVwuQzKZhFQqpZ9fLpehXC5DJBLpuNy9vT3IZDLQaDT8akogtKtn2NsR9voRAYNEaFBVFTmOw2w2a9pfqVQQALBUKmGpVEJRFBERUZIklGUZERHT6XRHZSqK0nJtPp9HANDLyWazps9BoWka8jyvt1XTNAQA/TPipS1EUURN0xzbUSqV9GsrlQoiIoqiGGg7WHn5fB4REWVZ1vcx7OpPDD7kbEMGc3TMuTAkSdL3iaKIpVIJZVlGWZaxVCrpDsULqqoiz/OWxziOw2KxiIiXjovjOFRV1XMZXsnn8ygIgv5ZFMWWhw9rN8OuHc3Xlkol5Hk+MEcny7Kp7ohocvbG84z1J4YDcrYhRBCElpvWCMdxKMsyqqqKkiTpPSmvyLLc4sgY2WwWFUVBTdNQFMWOnHknsN4tonWvG/H/bwAMu3bk83lTLzbodrA3EGO9rP43zfUnhgNytiGE3bR2vR+j07hKT00URb33alUHURQxnU53zdEy2APEaWiE4zjT8IBVO1RV1Z1fPp/vSm+S53n9TcNpuMJYf2I4+G+3x4iJ9sRiMZBlGRYWFmBmZgai0ajp+P7+vv73r1+/rlTWyMiI5f6bN2/CwcEB5PN5iMViVyrDKzzPw+vXr+Hk5MT2nHg8Dv/+/dM/W7UjGo0Cz/OQy+Xg8PDQZLegmJqagk+fPsGPHz8cy2uuPzH4kBohpMzMzADHcZbHxsbGYGlpKdDyl5eXIZ1OQ71eN+0vFAoQiUTazqg7qSqSyaTtddVqFS4uLuD8/NyXdkxNTcGrV69gZ2cHAABqtRpEIhHY29tzvC6ZTDq2wY5EIgGbm5vw9u1bGB0d9aUNxGBAzjakvHnzBtbW1lp6tQAAL1++hFu3bnn6vkKhAGNjYy37//7927Ivl8tBIpGAZ8+ewefPn03HUqkUCILQ1pHg5RCV5WbX42s0GrCwsAArKyuQSqXg69evtt///ft3uHbtmmM7GM+fP9frG41GIZ1Ow40bNxzrv7+/79gGJ0RRhPv37zue01x/YvAhZxtCCoUCnJ+fw5MnTyyP1+t1uHPnjq7LrdVqjt9Xq9UgHo+Dqqqm/RMTE3B0dNRS9tnZGaRSKYhGo8BxXEsvkDmuSCQCmUzGa/MsaTQakEwmQZZlGB0dhenpaVhfX7dtDwDowxtW7WDfWSgU4O7duy3Xx2IxSCaTlg+gq7C9vQ0TExOO5zTXnxgSejFQTNijqioKgtAy6SXLsj4JxHSasiyjoiiIaNaVsq15gqb5380kU6wsJvFiM+iVSgV5njfVh0nOSqUSZrNZ3+RgkiSZ6sK0vax9zbawkn4124xpdpvtIIoiqqqK2Wy2RWJ3FdLpdIuu1gqSfg0nvjvbYrGI6XQ6UNF2N8roFYIgtDgAJodi+9kNbacksMPKCdjJq+xgQn0naVqQuA1qsMP4UOrF74eCGoYXX52tX9FILNJHkiRENN8g7SKJ+hlmG7vNKClitmb2aNezZdFYVvZiDy83sOAKnuexUql0Vb7U7iHrph1MApZOp1FRFF97tu0Y5E5Cv2D1VpROp1v8URBvH745Wz+jkZjjMP4oRVFsEYgP4+uYoigoyzJqmoYcx1m+ZjfT7Iiv4mDY/5hFS/Wb42APKPY7JK3r8MAesIxisag/eK06f17f+trhm7P1OxqJ4zhTr431co1QJA5BEG5wcpyyLNu+abPQeD/wpEZgGstqtQpLS0sQiUSgUCgAAMDh4SHcu3fP8rpHjx7B9vY2LC8vgyzLrmZhU6kUHB8fQ6PRgLm5OXj//n3LOUwWVa1WLb+jU60nQRCDxfb2NkxPT3u+bnZ2Ft69e+dLHVxHkDG5iiiKsLa2BouLiwBwGWnE8DMaKZFIwPr6OpydnTkKxJ0icZCW6iUIAgAODg70wBYv3L592zd5o2tnG41GIRqNwvr6OszOzkIsFnPtOO2ikZyIx+NwenoKDx8+bCsQ95OrrAtLEP3EsHVGOonoi8VicHFx4Uv5ntZGaDQacHp6qi9e3YxTNFI8HoepqSlYXV11XR7HcfD48WPHc5wicZwcpyiKlpFMw/YDJAiiO3gasz05OQFRFC2PdRqNlMvlLHM0ffnyBeLxuOPTqF0kDnYQMkoQxGBit57Hnz9/bK+pVqu2a5R4xstsWjabtZVadRKNhHgpx2iWdCmK4kqm1AvpF9MA0+bvRvYPr80HAatlOJlmndlDEIQWKaWiKJZKqE4IPKjBCU3TbOVi7ehVUEPQqWH6DaubOMgHINm/+zYfBDp1mn5Kv3xdzzaVSsHIyAhkMhnY2Nhoe/7o6KinMVzG3t4e7O7uws7OTleXsSuXy20XGRk2sItj3GT/S7pp80EhlUrBt2/foFAo2M45NVMoFCAajfo2Qe/7ql8PHjxw5Wj9KKPb64UeHx/rY9aUCdcZu3qWy2UYGxuDSCRiOVbvBNnfGbu61Wo1fX3eYdaXb2xsQL1eh62trbbn5nI5qNfr/voyX/rHQ4LxFTYsmXBZeexfWSwWuzYmJ0mS6RVWEATTZ6uhHkmSsFKpmGzjlrDZny3KY4xihABf691kDLayOVsdjoV4E72BnK1LNE1rGfMJSyZcSZJMTgfA+4pgncAcG7uxWdhj841u5XhKpZKnOobR/sx5Gdshy7JvEypWuMkYbGdztiwn0RvI2bqkWCxaZkoNQyZc42pXzYttBI0gCKiqqu2EpdX6FZVKxfPDIKz2N/aYNU0LfHEeNxmDrWyuaVrHbSf8gZytS7LZrGWPKAyZcNl35/P5rt9Q+Xwes9ksSpJk2zbj6lqapukPAy+9rLDaX1EU01BF0Es2us0Y3LyiGftdKIri24LvhDfI2brEaXyRjd0F+SNuJ0ERBCHQ11c72Bix06u5se5GXaOXMduw2p85v25qvnmed1ypCtFcX2afbo3lE9ZQDjIXNBoNuH79uu1xp0y43WBrawumpqZacowFnUm20WjAx48fQRRF+P37t6u6GhMpuo3iC7P9Wbr0w8NDmJ+fB4DgMxA3Zwxux/z8vOtklURwkLNtolarQSaTMclDTk5OYHx83PYap0y4fqYdt1p7olwuQ7VahdXVVbi4uDAlfww6k+zTp09hcXERZmdnYXd31/Y8L5lk+83+jBcvXuh/B5mBmGHMGGwFZe8NH+Rsm/j58yckEgl4/fq1vu/o6AgmJyctz2+XCdevtONWa09Uq1WYm5uDlZUVAACQJAk+fPhgOieoTLKZTAbGx8chFovB5OQkbG5uWvbkvGaS7Sf7A1w+7FRVbRG+B5GBGMA+Y7ARyt4bUro8bNE38DyvT+TYjYW6yYTL5EZuxxVVVTVNghj3Gyd4WNmsbiwLRvPESBCZZJnkipXDxm2t9KudjmWG3f5sH1joaoPKQIxonzHYyDCmi+oHyNnawGaZNU2zFcG7yYTrV9pxVicvgvx+ziTbz/bvZQbiQUyEOiiQs7WBCdaNN6kRN5lwEf1NO47oLRNuP2eS7Wf79yoDMWXvDTfkbB24qqQoiLTjXuj3TLL9av9+z0BMBAM5WwecQmTd0Ou04/0O2Z8YJCKIJLwjCIIIGpJ+EQRBdAFytgRBEF2AnC1BEEQXIGdLEATRBf4HCZDthWOUTKEAAAAASUVORK5CYII=\"\u003e\u003c/p\u003e\n\u003cp\u003eIn Eq. (1), \u003cem\u003eX\u003csub\u003ek\u003c/sub\u003e\u003c/em\u003e is the \u003cem\u003ek\u003c/em\u003e-th element in pattern \u003cem\u003eX\u003c/em\u003e and \u003cem\u003eX̅\u003c/em\u003e is the mean of \u003cem\u003eX\u003c/em\u003e, while \u003cem\u003eY\u003csub\u003ek\u003c/sub\u003e\u003c/em\u003e and \u003cb\u003e\u003cstrong\u003e\u003cem\u003eȲ\u003c/em\u003e\u003c/strong\u003e\u003c/b\u003e are similarly defined for pattern \u003cem\u003eY\u003c/em\u003e. The results of the above computation in iteration \u003cem\u003ei\u003c/em\u003e form a time series of the correlation coefficients representing the similarity between the reference window and every other widow in the power trace. The time series of correlation coefficients obtained from the above procedure will cover all patterns of length \u003cem\u003ew\u003c/em\u003e in the given power trace.\u003c/p\u003e\n\u003cp\u003eTaking AES-128 as an example, if reference window \u003cem\u003ei\u003c/em\u003e is at the the starting position of an encryption round, we should have 9 peaks close or equal to 1 in the time series of correlation coefficients, in which \u003cem\u003er\u003csub\u003ei\u003c/sub\u003e\u003c/em\u003e\u003csub\u003e,\u003cem\u003ei\u003c/em\u003e\u003c/sub\u003e = 1 while the other eight peaks gives the starting positions of the other encryption/decryption rounds. In order to facilitate the searching procedure, we can select a threshold value \u003cem\u003eT\u003c/em\u003e such that position \u003cem\u003ej\u003c/em\u003e is judged as the starting position of a round if correlation coefficient \u003cem\u003er\u003csub\u003ei\u003c/sub\u003e\u003c/em\u003e\u003csub\u003e,\u003cem\u003ej\u003c/em\u003e\u003c/sub\u003e is larger than \u003cem\u003eT\u003c/em\u003e. The overall procedure is outlined in Algorithm 1.\u003c/p\u003e\n\u003cp\u003eIn iteration \u003cem\u003ei\u003c/em\u003e of the algorithm, the correlation coefficients are only calculated between reference window \u003cem\u003ei\u003c/em\u003e and other windows \u003cem\u003ej\u003c/em\u003e, \u003cem\u003ej\u003c/em\u003e \u0026sup3; \u003cem\u003ei\u003c/em\u003e (line 4) so that exact 9 qualified peaks will be found if a round starts at position \u003cem\u003ei\u003c/em\u003e. There is no need to calculate correlation coefficients \u003cem\u003er\u003csub\u003ei\u003c/sub\u003e\u003c/em\u003e\u003csub\u003e,\u003cem\u003ej\u003c/em\u003e\u003c/sub\u003e, \u003cem\u003ej\u003c/em\u003e \u0026lt; \u003cem\u003ei\u003c/em\u003e, as they have been calculated in previous iterations already.\u003c/p\u003e\n\u003cp\u003e\u003cbr\u003e\u003c/p\u003e\n\u003cdiv align=\"center\"\u003e\n \u003ctable border=\"1\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\"\u003e\n \u003ctbody\u003e\n \u003ctr\u003e\n \u003ctd width=\"100%\" colspan=\"5\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eAlgorithm 1:\u003c/strong\u003e Locating the encryption rounds\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"100%\" colspan=\"5\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eInput:\u003c/strong\u003e \u003cem\u003etrace\u003c/em\u003e: a power trace; \u003cem\u003ew\u003c/em\u003e: Window size; \u003cem\u003eT\u003c/em\u003e: Threshold; \u003cem\u003er_count\u003c/em\u003e: number of encryption round/operation;\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"100%\" colspan=\"5\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eOutput:\u0026nbsp;\u003c/strong\u003eLocations of encryption rounds\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.0606060606060606%\" valign=\"top\"\u003e\n \u003cp\u003e1\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"93.93939393939394%\" colspan=\"4\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003efor\u003c/strong\u003e \u003cem\u003ei\u003c/em\u003e = 0 to \u003cem\u003etrace\u003c/em\u003e.\u003cem\u003elength\u003c/em\u003e \u0026ndash; \u003cem\u003ew\u003c/em\u003e \u003cstrong\u003edo\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e2\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"90.81632653061224%\" colspan=\"3\" valign=\"top\"\u003e\n \u003cp\u003e\u003cem\u003epeak_N\u003c/em\u003e \u0026larr; 0\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e3\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"90.81632653061224%\" colspan=\"3\" valign=\"top\"\u003e\n \u003cp\u003e\u003cem\u003eref\u003c/em\u003e \u0026larr; \u003cem\u003etrace\u003c/em\u003e[\u003cem\u003ei:i+w\u003c/em\u003e]\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e4\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"90.81632653061224%\" colspan=\"3\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003efor\u003c/strong\u003e \u003cem\u003ej\u0026nbsp;\u003c/em\u003e= \u003cem\u003ei\u003c/em\u003e to \u003cem\u003etrace\u003c/em\u003e.\u003cem\u003elength\u003c/em\u003e-\u003cem\u003ew\u003c/em\u003e \u003cstrong\u003edo\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e5\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"87.75510204081633%\" colspan=\"2\" valign=\"top\"\u003e\n \u003cp\u003e\u003cem\u003ecorr\u003c/em\u003e \u0026larr; correlation_coefficient(\u003cem\u003eref\u003c/em\u003e, \u003cem\u003etrace\u003c/em\u003e[\u003cem\u003ej:j+\u003c/em\u003e\u003cem\u003ew\u003c/em\u003e])\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e6\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"87.75510204081633%\" colspan=\"2\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eif\u003c/strong\u003e \u003cem\u003ecorr\u003c/em\u003e \u0026gt; \u003cem\u003eT\u003c/em\u003e \u003cstrong\u003ethen\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e7\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"84.6938775510204%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cem\u003epeak_N\u003c/em\u003e = \u003cem\u003epeak_N\u003c/em\u003e + 1\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e8\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"90.81632653061224%\" colspan=\"3\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eend\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e9\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"90.81632653061224%\" colspan=\"3\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eif\u0026nbsp;\u003c/strong\u003e\u003cem\u003epeak_N\u003c/em\u003e == \u003cem\u003er_count\u0026nbsp;\u003c/em\u003e\u003cstrong\u003ethen\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.122448979591836%\" valign=\"top\"\u003e\n \u003cp\u003e10\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u0026nbsp;\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"3.061224489795918%\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003e\u0026nbsp;\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"87.75510204081633%\" colspan=\"2\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003ereturn\u003cem\u003e\u0026nbsp;\u003c/em\u003e\u003c/strong\u003e\u003cem\u003eref\u003c/em\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003ctr\u003e\n \u003ctd width=\"6.0606060606060606%\" valign=\"top\"\u003e\n \u003cp\u003e11\u003c/p\u003e\n \u003c/td\u003e\n \u003ctd width=\"93.93939393939394%\" colspan=\"4\" valign=\"top\"\u003e\n \u003cp\u003e\u003cstrong\u003eend\u003c/strong\u003e\u003c/p\u003e\n \u003c/td\u003e\n \u003c/tr\u003e\n \u003c/tbody\u003e\n \u003c/table\u003e\n\u003c/div\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e"},{"header":"3.\tEXPERIMENTAL RESULTS FOR AES AND DISCUSSION","content":"\u003cp\u003eThe proposed method is validated using NewAE ChipWhisper-Lite development board [20], while the encryption algorithm is AES-128. The encryption clock rate is 7.34 MHz while the sampling rate is four times of the encryption clock rate.\u003c/p\u003e\n\u003cp\u003eThe proposed method can be applied as long as the window size is not too far away from the exact length of an encryption round, and the effect of varying window width will be analyzed later.\u003c/p\u003e\n\u003ch2\u003e3.1. AES Result\u003c/h2\u003e\n\u003cp\u003eWe use the power trace given in Fig. 3 as the example. In this experiment, we set window size \u003cem\u003ew\u003c/em\u003e=4552 and threshold \u003cem\u003eT\u003c/em\u003e=0.9. Fig. 4(a) gives the time series of correlation coefficients for reference window 0 (i.e., the red box in Fig. 3). It can be seen that \u003cem\u003er\u003c/em\u003e\u003csub\u003e0,0\u003c/sub\u003e=1 while all other correlation coefficients are smaller than 0.6. The result indicates that position 0 does not start an encryption round.\u003c/p\u003e\n\u003cp\u003eFig. 4(b) illustrates the time series of correlation coefficients for reference window 3790, which is the starting position of the first encryption round. It can be seen that there are 9 peaks whose values are very close to 1, and the value is equal to 1 at position 3790. The results indicate that we have successfully locate the first 9 encryption rounds.\u003c/p\u003e\n\n\u003ch2\u003e3.2. Effect of Pre-processing\u003c/h2\u003e\n\u003cp\u003eResults in Fig. 4(b) are obtained from the pre-processed power trace. In order to demonstrate the effect of pre-processing, we also calculate the correlation coefficients obtained from the original power trace (i.e., without pre-processing), and the results are provided in Fig. 5. In this case, the difference between peak and non-peak values are significantly smaller.\u003c/p\u003e\n\u003ch2\u003e3.3. Effect of Window Size\u003c/h2\u003e\n\u003cp\u003eThe impact of varying window size is assessed through experiment, and the general is outlined as follows. (1) First, a pre-processed power trace is selected, with the reference window located at the starting position of the first round. (2) Let the length of an encryption round be \u003cem\u003eW\u003c/em\u003e. In each try, the window size is set to \u0026alpha;\u003cem\u003eW\u003c/em\u003e, where \u0026alpha; is a real number used to adjust the window size. (3) Execute Algorithm 1 to find out set \u003cem\u003eP\u003c/em\u003e of all qualified peak values. (4) Let #\u003cem\u003eIR\u003c/em\u003e be the number of identical rounds in the encryption process. The normalized peak value \u003cem\u003eNP\u003c/em\u003e is defined as \u003cimg src=\"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAGkAAAAXCAYAAAAIqmGLAAADh0lEQVRoge1aPU4rPRS9eTuwRE3jBdB4BTTeAYPECizRI3kHpkYirMA0lJZAlEYUqaajckqqgSzhfEWejcd2eNGDPBJ9OdJIyZ2J584598+jTACA9thq/PppB/b4M/Yi7QD2Iu0A9iLtAPYi7QD2Iu0Atlqky8tLmkwmK4+np6efdpGIln7e3t5u7gZogIhAROj7vrKFEAAA3vtkIyIwxqC1bi331wghNNft+x5EBO/9t97vb8E5xzAMI5uUMtkYY6NzOXfxGUo+iSg9d1MkYwyklCNytNYwxlSOTKdTAB/E5cJ+B6bTaVOQruu2QiRrbTM4Oefps5SyOi+lhFKqskWOY4B679siKaXQ9/3oRl3XVQJwzqts2wRxQggIIb593e8A5zxVF2AZ4GVGxKP8nXOusuV8cs5Xi9R1HYBlmkYHSpJCCEnEYRiglBqJWmKV40TUjLQcMUvLTN4UrLWpKmitQURV1APLEhW5yhFCSM/kva/8DiFUosXMAZZ8aq0T59XgMJ/PiXNORESnp6f0+Pg4skXMZjMKIdBkMqGDgwN6f3+nu7u7z3rfyuP+/v7Tvnl0dETGGLq4uKD5fP7ptV9FXF9KSTc3N3RyckIhBLq+vq6uvbq6ovPz88r++vpKx8fHRET0/PxMh4eHo/Oz2YyklJVtsVgkPheLxQcvrSiy1gIAnHMQQsA5V0WDUuqfRTbwEWl5adkkpJSpdA/D0Iz8VgmWUjarRc5VizulVOptXdeNzlciKaVGRDDGoJSqek2sl+ui5TitWe6iX3FI+SpyIvMpLEdeuq21lSBa6xTMJYwxiZvW+i3u8h5lrR1xMhJpGIZqnFRKVVEUe8S/imprbbP2A0ufhRBpIs2zzVoLxlhz3M2jtiTMe59E6fsejLFRk488rUI+ZJXXtbgrbfF7xIj9KEg+UpaqAsshYt0M+CpiWSmj0RgD5xy893DOQUqJEAK01on01u+AZRY45zAMA6SU1dRqjIFSCowxMMaqjLHWflrqc17KDGxx17Ll+8PmdLdNEEJUkR4jOdqn02mK9Lw0l2U1F49+b8BbZOf9qIVy7N40tlqkOP6uOiKRUZhyb9fKpHzrsArlG4Ic3vvmOL5JbLVI60IIAcZYtRls9aQ4NKzKlNgPyo3mT2IC7PZ/HN7e3ujs7OyPe61dxla/BV8HLy8v9PDwsDVvxDeBnc+k/wP+AwPiFsjd0x06AAAAAElFTkSuQmCC\" alt=\"\" /\u003e. When all the identical rounds are correctly identified, \u003cem\u003eNP\u003c/em\u003e should be smaller than 1 but also very close to 1.\u003c/p\u003e\n\u003cp\u003eThe experiment is carried out using the power trace given in Fig. 3. Since the encryption algorithm is AES-128, #\u003cem\u003eIR\u003c/em\u003e is 9. We have executed the above procedure with various window sizes, and the results are summarized in Table 1 The results show that the proposed method is effective in the range between 0.5\u0026acute;\u003cem\u003eW\u003c/em\u003e to \u003cem\u003eW\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eTable 1. Window size vs. normalized peak value.\u003c/p\u003e\n\u003ctable border=\"1\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\"\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd width=\"12.76595744680851%\"\u003e\n\u003cp\u003e\u0026alpha;\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"12.76595744680851%\"\u003e\n\u003cp\u003e0.005\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.01\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.5\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e1.0\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e1.5\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e2.0\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e2.5\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e3.0\u003c/p\u003e\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd width=\"12.76595744680851%\"\u003e\n\u003cp\u003e\u003cem\u003eNP\u003c/em\u003e\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"12.76595744680851%\"\u003e\n\u003cp\u003e19.662\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e1.431\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.981\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.985\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.876\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.877\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.768\u003c/p\u003e\n\u003c/td\u003e\n\u003ctd width=\"10.638297872340425%\"\u003e\n\u003cp\u003e0.768\u003c/p\u003e\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThe reasons that smaller and larger window sizes cannot be used are explained through examples in Fig. 6, in which two time series of correlation coefficients are plotted for \u0026alpha;=0.005 and \u0026alpha;=2. In the case of a small window size (\u0026alpha;=0.005), many similar patterns can be found in the power trace, leading to many correlation coefficients larger than threshold \u003cem\u003eT\u003c/em\u003e, as shown in shown in Fig. 6(a). As a result, the cardinality of set \u003cem\u003eP\u003c/em\u003e, returned by Algorithm 1, will increase if the window size shrinks.\u003c/p\u003e\n\u003cp\u003eOn the other hand, if the window size is 2\u003cem\u003eW\u003c/em\u003e, only the first 8 rounds can be correctly located, as shown in Fig. 6(b). In this case, the reference window contains the pattern consisting of the first two rounds, while each peak in Fig. 6(b) matches a pattern covering two consecutive encryption rounds. The sliding window at the starting position of round 9 convers the last two rounds; however, since the operations in the last round is not the same as the other 9 rounds, the correlation coefficient is relatively small.\u003c/p\u003e\n\u003cp\u003eObviously, the best choice of window size should be \u003cem\u003eW\u003c/em\u003e. However, if initially\u003cem\u003e\u0026nbsp;W\u003c/em\u003e is unknown, one can apply the following procedure to determine \u003cem\u003eW\u003c/em\u003e. (1) From a given power trace, manually select a window size that falls between \u003cem\u003eW\u003c/em\u003e and \u003cem\u003eW\u003c/em\u003e/2. (2) Execute Algorithm 1 to find out peaks. (3) \u003cem\u003eW\u003c/em\u003e is the distance between two consecutive peaks.\u003c/p\u003e"},{"header":"4.\tAPPLICATION TO OTHER CRYPTOGRAPHIC ALGORITHMS","content":"\u003cp\u003eThe proposed method can also be used to locate computation operations in the power traces of other cryptographic algorithms. The cases of RSA and ECC are studied in this section.\u003c/p\u003e\n\u003ch2\u003e4.1. RSA\u003c/h2\u003e\n\u003ch3\u003e4.1.1. Regular Implementation\u003c/h3\u003e\n\u003cp\u003eThe encryption process of RSA involves repeated modular exponentiation operations. In the process, the square operation will be executed in every key bit while an additional multiplication operation is executed if the key bit is 1. Therefore, we need to find the patterns corresponding to the square operations to locate encryption operations, so the window size should be close to the time period used for the square operation.\u003c/p\u003e\n\u003cp\u003eFig. 7(a) gives a power trace of RSA encryption in which the key length is 16, while Fig. 7(b) show the results of round locating. In this experiment, the window size is \u003cem\u003ew\u003c/em\u003e=5100 sampling periods, which is the time required to complete a square operation. It can be seen that exact 16 qualified peaks appear in Fig. 16(b).\u003c/p\u003e\n\u003cp\u003eIn this case, the proposed method can also be used for SPA, as the distance between two consecutive peaks can be used to extract the corresponding key bit. There are two types of distances; the longer distance implies that the corresponding bey bit is \u0026lsquo;1\u0026rsquo; while the shorter distance means the key bit is \u0026lsquo;0\u0026rsquo;. The 16 peaks in Fig. 7(b) can be used to extract the first 15 bits of the encryption key, which is\u0026nbsp;1000_0001_0100_000x. The last key bit cannot be identified directly using the proposed method.\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e\n\u003ch3\u003e4.1.2. Implementation with Montgomery Power Ladder\u003c/h3\u003e\n\u003cp\u003eThe execution time variation due to different key bit values can be eliminated by using Montgomery power ladder (MPL) [21]. In this case, the proposed method cannot be used for SPA; still, the locations of every bit can be located in the process. An example is shown in Fig. 8, in which Fig. 8(a) gives the power trace and Fig. 8(b) is the locating results obtained with \u003cem\u003ew\u003c/em\u003e=2220. It can be seen that 16 peaks appear in Fig. 8(b), while all distances between consecutive peaks are roughly equal.\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e\n\u003ch2\u003e4.2. ECC\u003c/h2\u003e\n\u003cp\u003eIn the encryption process of ECC, the \u0026ldquo;double\u0026rdquo; operation is executed for all key bits while \u0026ldquo;add\u0026rdquo; is executed only if the key bit is \u0026lsquo;1\u0026rsquo;. Therefore, in a straightforward implementation of ECC, the locating process is similar to that of RSA. In this case, we need to locate \u0026ldquo;double\u0026rdquo; operations in a power trace. An example is given in Fig. 9. Fig. 9(a) is the power trace of an ECC encryption with a 8-bit key, while Fig. 8(b) is obtained by locating \u0026ldquo;double\u0026rdquo; operations with \u003cem\u003ew\u003c/em\u003e=5100.. It is clear that there are 8 peaks in Fig. 9(b), which indicates that computation operations corresponding to the 8 key bits are located. Furthermore, the peak positions can be used for SPA, since a longer distance between two peaks imply the computation is for key bit \u0026lsquo;1\u0026rsquo;. From Fig. 9(b), it can be seen that the encryption key is 1010_010x.\u003c/p\u003e\n\u003cp\u003eMPL has also been proposed as a countermeasure to SPA for ECC [21]. In this case, the locating results are peaks separated by the same distance. The process is similar to that of RSA with MPL.\u003c/p\u003e"},{"header":"5.\tCONCLUSION","content":"\u003cp\u003eWe propose a method for automatic location of cryptographic operations in power traces. The proposed method is achieved by using sliding windows to calculate correlation coefficients that are used to locate encryption rounds in AES. Experimental results show that the proposed method can effectively locate encryption rounds in AES, and the method is applicable to other cryptographic algorithms as well, including RSA and ECC.\u003c/p\u003e\n\u003cp\u003eThis approach gives test laboratories the means to perform side-channel analysis without the need for additional trigger signals. Compared with previous methods, the proposed method can achieve accurate power trace alignment with lower computation resources.\u003c/p\u003e"},{"header":"References","content":"\u003col\u003e\n\u003cli\u003eTehranipoor M., Wang C. (eds.): Introduction to Hardware Security and Trust. Springer (2012)\u003c/li\u003e\n\u003cli\u003eGoertzel K.M., Hamilton B.A. Integrated circuit security threats and hardware assurance countermeasures. CrossTalk 26(6), 33-38 (2013)\u003c/li\u003e\n\u003cli\u003eRostami M., Koushanfar F., Karri R.: A primer on hardware security: models, methods, and metrics. Proc. IEEE 102(8), 1283\u0026ndash;1295 (2014)\u003c/li\u003e\n\u003cli\u003eSklavos N., Chaves R., Di Natale G., Regazzoni F. (eds.): Hardware Security and Trust, Springer (2017)\u003c/li\u003e\n\u003cli\u003eDas D., Maity S., Nasir S.B., Ghosh S., Raychowdhury A., Sen S. High efficiency power side-channel attack immunity using noise injection in attenuated signature domain. In Proc. 2017 IEEE International Symposium on Hardware Oriented Security and Trust (HOST), 62-67 (2017)\u003c/li\u003e\n\u003cli\u003eDas D. et al.: ASNI: attenuated signature noise injection for low-overhead power side-channel attack immunity. IEEE Trans. CAS-I 65(10), 3300\u0026ndash;3311 (2018)\u003c/li\u003e\n\u003cli\u003eKocher, P.C.: Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems. In: Koblitz, N. (eds) Advances in Cryptology \u0026mdash; CRYPTO \u0026rsquo;96. LNCS 1109. Springer, Berlin, Heidelberg (1996).\u003c/li\u003e\n\u003cli\u003eMayer-Sommer, R.: Smartly analyzing the simplicity and the power of simple power analysis on smartcards. In: Ko\u0026ccedil;, \u0026Ccedil;.K., Paar, C. (eds) Cryptographic Hardware and Embedded Systems \u0026mdash; CHES 2000. NCS 1965. Springer, Berlin, Heidelberg (2000)\u003c/li\u003e\n\u003cli\u003eKocher, P., Jaffe, J., Jun, B.: Differential Power Analysis. In: Wiener, M. (eds) Advances in Cryptology - CRYPTO\u0026rsquo; 99, LNCS 1666, 388\u0026ndash;397. Springer, Berlin, Heidelberg. Springer (1999)\u003c/li\u003e\n\u003cli\u003eBrier, E., Clavier, C., Olivier, F.: Correlation power Analysis with a leakage model. In: Joye, M., Quisquater, JJ. (eds) Cryptographic Hardware and Embedded Systems (CHES 2004), LNCS 3156. Springer, Berlin, Heidelberg (2004)\u003c/li\u003e\n\u003cli\u003eRechberger, C., Oswald, E.: Practical template attacks. In: Lim, C.H., Yung, M. (eds) Information Security Applications (WISA 2004), LNCS 3325, 440-456,. Springer, Berlin, Heidelberg (2005).\u003c/li\u003e\n\u003cli\u003eHospodar, G., Gierlichs, B., De Mulder, E. et al.: Machine learning in side-channel analysis: a first study. J. Cryptogr. Eng. 1, 293\u0026ndash;302 (2011)\u003c/li\u003e\n\u003cli\u003eLerman, L., Poussier, R., Markowitch, O. et al.: Template attacks versus machine learning revisited and the curse of dimensionality in side-channel analysis: extended version. J. Cryptogr. Eng. 8, 301\u0026ndash;313 (2018)\u003c/li\u003e\n\u003cli\u003eBartkewitz, T., Lemke-Rust, K.: Efficient template attacks based on probabilistic multi-class support vector machines. In: Mangard, S. (eds) Smart Card Research and Advanced Applications (CARDIS 2012), LNCS 7771, 263\u0026ndash;276. Springer, Berlin, Heidelberg (2013)\u003c/li\u003e\n\u003cli\u003eBecker G., et al.: Test vector leakage assessment (tvla) methodology in practice. Proc. Intl. Cryptographic Module Conf. (2013)\u003c/li\u003e\n\u003cli\u003eISO/IEC 17825. https://www.iso.org/standard/60612.html.\u003c/li\u003e\n\u003cli\u003eTian Q., Shoufan A., Stoettinger M., Huss S.H.: Power trace alignment for cryptosystems featuring random frequency countermeasures. Proc. 2012 IEEE Second International Conference on Digital Information Processing and Communications (ICDIPC), 51-55. IEEE (2012)\u003c/li\u003e\n\u003cli\u003eTian Q., Huss S.H.: A general approach to power trace alignment for the assessment of side-channel resistance of hardened cryptosystems. Proc. 2012 IEEE Eighth International Conference on Intelligent Information Hiding and Multimedia Signal Processing, 465-470. IEEE (2012)\u003c/li\u003e\n\u003cli\u003eTrautmann, et al.: Semi-automatic locating of cryptographic operations in side-channel traces. IACR Trans. Cryptographic Hardware and Embedded Systems (TCHES), 2022(1), 345-366. (2022)\u003c/li\u003e\n\u003cli\u003ehttps://www.newae.com/chipwhisperer.\u003c/li\u003e\n\u003cli\u003eJoye, M., Yen, SM.: The Montgomery Powering Ladder. In: Kaliski, B.S., Ko\u0026ccedil;, \u0026ccedil;.K., Paar, C. (eds) Cryptographic Hardware and Embedded Systems (CHES 2002), LNCS 2523. Springer, Berlin, Heidelberg (2003).\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":false,"hideJournal":true,"highlight":"","institution":"","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"side-channel attack (SCA), power analysis, power trace, AES, RSA, ECC","lastPublishedDoi":"10.21203/rs.3.rs-2995521/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-2995521/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"Data encryption is critical for information security. Previous studies show that power analysis is a powerful tool for side-channel attack (SCA) against cryptographic modules. Therefore, it is essential to carry out power analysis to assess the vulnerability of cryptographic modules. The success of power analysis relies on aligned power traces, which is not easy without an external trigger point. Locating cryptographic operations in a power trace can be tedious, so it is desirable if we can achieve automatic power trace alignment. In this paper, we propose an automatic power trace alignment method so that operations in power traces and be located without external trigger points. Experimental results show that the proposed method can be applied to various ciphers, including AES, RSA, and ECC.","manuscriptTitle":"Automatic Power Trace Alignment for Side-Channel Analysis","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2023-06-02 14:58:19","doi":"10.21203/rs.3.rs-2995521/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"572cf360-5fbb-44a4-b117-b5284bc3bf8c","owner":[],"postedDate":"June 2nd, 2023","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[],"tags":[],"updatedAt":"2023-06-16T06:44:24+00:00","versionOfRecord":[],"versionCreatedAt":"2023-06-02 14:58:19","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-2995521","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-2995521","identity":"rs-2995521","version":["v1"]},"buildId":"J0_U0BvcaRcwD8yVFaRlm","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.